ICAM Architect will define and maintain the enterprise ICAM architecture across policy enforcement and information, enterprise management, and resource and policy management modernization workstreams. This includes developing end-to-end architectural patterns for identity, attribute services, authorization flows, policy distribution, and resource and role lifecycle management. The architect will partner with the Technical Lead to validate modernization roadmaps, architectural decisions, and integration strategies for on-premises and cloud-native, microservices-based ICAM components. Additional duties include translating mission needs into technical requirements, sequence diagrams, data models, interface specifications, and system architecture artifacts; overseeing the design of modern policy enforcement and information interfaces supporting attribute-based access control, dynamic policy evaluation, and event-driven decision making; architecting enterprise management and resource and policy management capabilities including resource registration, policy lifecycle automation, attribute orchestration, and enterprise authorization services; providing architectural guidance to DevOps and software engineering teams; conducting architectural reviews, risk assessments, and compliance verification for modernization milestones and incremental releases; and serving as a senior technical advisor to program management to support planning and customer engagement.
Required Skills/Experience:- Enterprise, solutions, or systems architecture supporting complex modernization, security, or ICAM programs
- Design of distributed systems, microservices architectures, and cloud-native solutions
- ICAM modernization, enterprise identity technology, or authorization and policy services
- Agile methodologies including Program Increment (PI) planning, architectural runway development, and iterative delivery
- Definition of architectural goals, strategic plans, and detailed implementation guidance
Preferred Skills/Experience:- Kubernetes, OpenShift, or container orchestration platforms
- Java and/or Python for modern application integration
- GitOps tools for managing modern environments
- Identity and authorization standards including X.509, SAML, OAuth2, OIDC, and LDAP
- ICAM solution architecture using Oracle or other enterprise-grade identity platforms
- ABAC and RBAC model definition, policy-as-code, and Zero Trust-aligned access patterns
- Support of Intelligence Community authorization or identity systems
Qualifications:- Master's degree in a STEM field, or Bachelor's degree in a STEM field
- Active Top Secret/SCI clearance required; must be willing and able to obtain a polygraph within the customer's timeline after hire
- Ability to obtain Security+ certification within 90 days of hire
- Enterprise architecture framework certifications (preferred)
For positions requiring a federal security clearance, your clearance level must be clearly identified on your resume.